As some have noted, the TCP Timestamps option allows people with knowledge of the Linux TCP stack to accurately estimate the uptime of a machine.

While the timestamps can be disabled, they perform a valuable function (they can be used to determine round-trip-time which is fairly vital to preventing wastefully retransmitting data). See RFC 1323.

Currently, a number of OSs (Linux included, I believe) start this counter out at zero and then count up in a predictable fashion. It is therefore possible to determine uptime if you can identify the OS.

Nothing more than randomizing the initial value would be necessary to prevent this data from slipping. Since this information can be useful in selecting machine to attack (prioritize on machines that haven't rebooted in a while and thus may have more holes), it is probably a good idea to close this before anyone decides to exploit it.

you completely missed the point Kagato was asking. If it's 1, you can determine the uptime, if it's 0 it's not RFC 1323. He asked for randomization of tcp_timestamps so neither it violates RFC 1323 nor you can determine the uptime.

Note that if you only randomise the timestamp at boot-up, an attacker could still monitor your machine for timestamp changes over time to know when you went up. It'll be a lot harder for a script kiddie, of course.

The way to "fool" people is to instead of using the jiffies value for the timestamp, use 0 as the initial timestamp for the connection. This doesn't break RFC and does what you want. However, I've looked at doing this a few times in Linux, and though my knowledge of that area of the code is minimal at best, it looked like jiffies were too ingrained into the code to be able to make a trivial change to use this new timestamping method.

Around early 2001, when this issue first broke on Bugtraq and the NMap development list, there were some calls for the various *nix kernels to do exactly that. However, ony a patch for OpenBSD 2.7/2.8 was ever released (see URL below), and by and far the various kernel hackers (including Linux) refused to develop similar patches.

I'm not sure why this hasn't been done for Linux. It's a small issue, to be sure, but there's no reason why you have to tell someone scanning you how long your computer's been up. And as mentioned earlier, disabling tcp_timestamps, while solving the immediate issue, does go against rfc 1323.

HelloI'm sorry that I am updating topic after so much years passed by but I am curious about current situation with tcp timestamp in operating systems/networking stacks and I think it is a good place to ask. Is still OpenBSD the only system that randomizes value of timestamp at the beggining of tcp connection(or setting constant value such as 0)? Does grsecurity changes the behaviour of Linux network stack in regard to timestamps?

ErroR|51 wrote:That would be, indeed, a nice hack.Can't understand why they are refusing to do such a patch, though.

Because they think they are superior or they are bought and payed for.They don't care about your security concerns, besides what do you have to worry about, if you are violating the US/Western moral law code you deserve to be thrown in prison forever. Every knee must bend to the religion of democracy, freedom, and ... well GIRLS NOT BRIDES, GIRLS NOT BRIDES, FERT, EMPOWERMENT (and yea 5 or 6 million men in prison in the USA, being raped by homosexuals and getting aids!).

Think how bad the men in afghanistan have it: they are blown to bits in their houses while the mighty moral force of these United States of America liberate their land so that girls will never be married to a man again (allowed in their muslim religion, also allowed in the old testament, and vedic religions, so on and so on... but not allowed in the USA religion/belief system (US Code)... and the USA is the god of this world so we all must obey obey obey)

Why is systemd being rammed down our throats? Because some people are bought and payed for.Give someone a million dollars and they'll do whatever you want, because money is the only good thing in western life. The natural pleasures are all outlawed and the men who find them are persecuted.

Don't worry if you're in line, you're in the club then. Be happy about the bugridden garbage being dumped on us: it could be worse: it could be bombs from drones like other people who disobey the USA belief system suffer under.